Show filters
104 Total Results
Displaying 41-50 of 104
Sort by:
Attacker Value
Unknown

CVE-2022-23378

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
A Cross-Site Scripting (XSS) vulnerability exists within the 3.2.2 version of TastyIgniter. The "items%5B0%5D%5Bpath%5D" parameter of a request made to /admin/allergens/edit/1 is vulnerable.
Attacker Value
Unknown

CVE-2022-21715

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. A cross-site scripting (XSS) vulnerability was found in `API\ResponseTrait` in Codeigniter4 prior to version 4.1.8. Attackers can do XSS attacks if a potential victim is using `API\ResponseTrait`. Version 4.1.8 contains a patch for this vulnerability. There are two potential workarounds available. Users may avoid using `API\ResponseTrait` or `ResourceController` Users may also disable Auto Route and use defined routes only.
Attacker Value
Unknown

CVE-2022-21647

Disclosure Date: January 04, 2022 (last updated February 23, 2025)
CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulnerability, and possibly execute existing PHP code on the server. We are aware of a working exploit, which can lead to SQL injection. Users are advised to upgrade to v4.1.6 or later. Users unable to upgrade as advised to not use the `old()` function and form_helper nor `RedirectResponse::withInput()` and `redirect()->withInput()`.
Attacker Value
Unknown

CVE-2021-40975

Disclosure Date: October 01, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in application/modules/admin/views/ecommerce/products.php in Ecommerce-CodeIgniter-Bootstrap (Codeigniter 3.1.11, Bootstrap 3.3.7) allows remote attackers to inject arbitrary web script or HTML via the search_title parameter.
Attacker Value
Unknown

CVE-2020-35200

Disclosure Date: December 12, 2020 (last updated February 22, 2025)
Ignite Realtime Openfire 4.6.0 has plugins/clientcontrol/spark-form.jsp Reflective XSS.
Attacker Value
Unknown

CVE-2020-35201

Disclosure Date: December 12, 2020 (last updated February 22, 2025)
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp users Stored XSS.
Attacker Value
Unknown

CVE-2020-35199

Disclosure Date: December 12, 2020 (last updated February 22, 2025)
Ignite Realtime Openfire 4.6.0 has create-bookmark.jsp groupchatJID Stored XSS.
Attacker Value
Unknown

CVE-2020-35202

Disclosure Date: December 12, 2020 (last updated February 22, 2025)
Ignite Realtime Openfire 4.6.0 has plugins/dbaccess/db-access.jsp sql Stored XSS.
Attacker Value
Unknown

CVE-2020-35127

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
Ignite Realtime Openfire 4.6.0 has plugins/bookmarks/create-bookmark.jsp Stored XSS.
Attacker Value
Unknown

CVE-2020-25093

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in blog.php. within application/views/templates/clothesshop, application/views/templates/onepage, and application/views/templates/redlabel.